← All posts

Voter tracking: the spreadsheet that makes coercion actually work

Someone in North Macedonia was keeping a list of who showed up to vote — and that list is the whole reason a secrecy rule, by itself, will never be enough.

It is a Tuesday in late 2025, somewhere in a municipal office in North Macedonia, and a public-sector worker is trying to decide something very simple: whether to vote.

Not who to vote for. Whether to show up at all.

Because someone — their employer, their party contact, the person who arranged their contract — has made it clear that showing up matters. And that not showing up will be noticed. And that how this works is: they track who votes, and they know how to find out the rest.

This is not a conspiracy theory. It is an observation recorded in an official international monitoring report.

The OSCE's election-monitoring body, ODIHR, deployed observers to North Macedonia's 2025 local elections and issued its final report in April 2026. The findings were specific: instances of voter tracking on and around election day; allegations of vote-buying; pressure on public-sector employees and voters. ODIHR recommended that the authorities "effectively investigate allegations of vote-buying, pressure on voters, and misuse of administrative resources."

That word — tracking — is doing a lot of work. Sit with it for a moment.


The spreadsheet is the product

Voter tracking is not surveillance in the science-fiction sense. It does not require cameras or facial recognition or a classified intelligence program.

It requires a list.

Electoral rolls are public, or semi-public, in most democracies — because transparency is a democratic value. Officials know who is registered. Precinct workers know who collected a ballot. Turnout data is collected by law. None of this is secret. None of it is supposed to be weaponizable.

But combine a registration list with a turnout log, hand it to someone with power over people's jobs or contracts or public benefits, and you have built a compliance-checking machine out of entirely legal components.

The spreadsheet is the product. The election is the occasion.

The coercer does not need to know how someone voted. Not yet. They only need to know whether they showed up. Show-up compliance is step one: the voter demonstrates they went to the booth. The implicit threat — that failure to appear will have consequences — is enforced by the data that already exists.

This is why ODIHR does not record "voter tracking" as a footnote. It records it as an integrity finding. Because tracking is the operational infrastructure of coercion. Remove the tracking, and the threat becomes unenforceable.


Why "we have a secrecy rule" doesn't solve it

The standard reassurance goes like this: elections have secret ballots; no one can see how you voted; therefore coercion cannot work.

This is true as far as it goes. And it does not go far enough.

The U.S. Court of Appeals for the First Circuit laid out the mechanism with unusual clarity in Rideout v. Gardner (2016). The case was about ballot selfies — whether voters could photograph their marked ballots. The court traced the history directly: secret-ballot reforms were adopted specifically "to combat widespread vote buying and voter intimidation," practices that depend on a buyer or coercer being able to verify the vote. A photograph of a marked ballot restores that proof. Which is why it became a tool.

The court's reasoning is the key insight: secrecy defeats coercion because it breaks verification. If the coercer cannot confirm delivery, the threat loses its teeth. The ballot selfie matters not because anyone particularly wanted to sell vacation photos of their vote, but because it re-opens the verification market that secrecy closed.

Now notice what voter tracking does. It is not ballot secrecy that tracking defeats. It is the behavioral layer beneath it.

A coercion scheme with tracking does not need to know your choice. It only needs to know your compliance. Show up → presumed in line → safe. Don't show up → problem. And if you show up but are suspected of defection, the next layer of pressure is already waiting: prove how you voted, or face consequences anyway.

Secrecy protects the ballot. It does not protect the person casting it.


The anatomy of pressure on public-sector employees

The North Macedonia findings did not emerge in isolation. ODIHR has been recording variations on this pattern for years across the region.

In Albania's 2021 parliamentary elections, ODIHR documented widespread allegations of vote-buying and pressure on voters, including concerns about voters being pressured to disclose whether and how they voted. The report called for guaranteeing the right to a free and secret vote and preventing any form of pressure on voters.

In Georgia's October 2024 parliamentary elections, the ODIHR mission found vote secrecy compromised in over 30 percent of its observations — not just because of ballot-box design, but because the physical environment around the ballot allowed others to observe. Observers recorded intimidation and pressure on voters that compromised their ability to cast a ballot without fear of retribution.

In Kyrgyzstan's 2017 presidential election, ODIHR found cases of pressure on voters and vote-buying, and recommended that authorities guarantee the right to a free and secret choice and prevent any form of pressure on voters to disclose how they voted.

The pattern is consistent and it is not limited to any one region or regime type. The mechanism is the same: someone with leverage over a voter's livelihood, housing, benefits, or safety uses that leverage to direct or monitor electoral behavior. The ballot secrecy rule does not reach the relationship between the employer and the employee. It does not reach the landlord and the tenant, the local official and the dependent, the party operative and the precinct worker.

What it does not reach, it does not protect.


The deeper problem: coercion needs a receipt

Here is what makes the North Macedonia situation technically interesting, not just politically distressing.

The coercion market — like any market — requires a verification mechanism. The buyer needs evidence of delivery. The coercer needs proof of compliance. Without that, the transaction falls apart.

This is exactly what the secret ballot was designed to do in 1856. The Australian Electoral Commission records that voting was public before then, which "left voters vulnerable to intimidation and coercion," and that the secret ballot was implemented to remove that vulnerability. The United Kingdom followed in 1872 with the Ballot Act, which replaced open voting — where your choice was declared aloud or written in a public book — with a private booth, a uniform state-printed ballot, a sealed box.

The logic was architectural, not legal. The law did not say "coercion is forbidden and we trust you not to do it." The law said: "here is a physical system in which coercion cannot be verified, so it cannot be enforced."

That is the distinction that matters now.

A secrecy rule says: you may not reveal your vote. A secrecy architecture says: your vote is provably unlinkable to you, even if you wanted to prove it.

These are different things. The rule depends on compliance and enforcement. The architecture depends on mathematics.

Voter tracking exploits the gap between them. Even with a perfect secrecy rule on the ballot itself, a traceable footprint exists at every step around it: registration, check-in, turnout, and — in some systems — the timing and channel of the vote. That footprint is what tracking monetizes.

What defeats coercion is not a rule. It is a choice provably unlinkable to the person who made it.


What "provably unlinkable" actually means

This is not an abstraction. It has concrete design implications.

Consider what a coercer actually needs. They need, at minimum, to confirm that a specific person voted in a way that can be connected to a specific observable act. If they can break that connection — technically, not just legally — the enforcement mechanism collapses.

Cryptographic voting systems designed around this principle do not just hide your vote behind a privacy rule. They produce a public record that mathematically cannot be traced back to an individual voter, even by the election authority itself, while still allowing anyone to verify that every cast vote was counted and no phantom votes were added.

This is the difference between "we promise not to look" and "looking is cryptographically impossible."

The Swiss Post internet voting episode of 2019 is instructive, though from the opposite direction. Researchers Sarah Jamie Lewis, Olivier Pereira, and Vanessa Teague analyzed the published source code of Switzerland's e-voting system and found that what looked like a mathematically sound verification proof had a trapdoor built in — meaning an authority who knew the trapdoor values could generate a proof that appeared valid while having altered votes. The verifiability claim was real-looking but hollow.

The lesson is not that cryptography fails. It is that a verifiability claim must be independently inspectable to be worth anything. "We use a cryptographic system" is not a guarantee. "Here is the code and the proof; check it yourself" is the beginning of one.


What the monitoring reports cannot tell you

The ODIHR findings on North Macedonia's 2025 elections are important. They are also, by design, limited.

An election observation mission can record what its observers saw. It can document allegations. It can note patterns. What it cannot do is reconstruct the private calculations of every voter who showed up to a booth under duress, or every voter who stayed home because staying home felt safer.

The number of votes coercion moved, in any election where it occurs, is not in any report. It is unknowable.

That is the real argument for a different architecture. Not that coercion always changes outcomes — sometimes it does not. Not that officials are always complicit — sometimes they genuinely try to stop it. But that a system which depends on the absence of coercion, and provides no independent way to verify that absence, is asking you to trust a claim no one can actually prove.

The same logic runs through every verifiability gap this blog has covered: the tally sheet that cannot be authenticated, the QR code the voter cannot read, the audit that confirms a result using a method that itself carries irreducible error. In every case, the official account says "it was fine." In every case, the structural question remains: how would anyone know?

Voter coercion is the most human version of that gap. The ballot goes in the box unobserved. The result is reported. And somewhere between the booth and the tally, a voter who was tracked and pressured either complied or found a private way to resist — and no one outside that voter's head can tell which.


The fix is architectural, not administrative

ODIHR's recommendation in North Macedonia — "effectively investigate allegations" — is the right legal response. It is not the structural fix.

The structural fix is a voting system designed so that:

  1. Turnout is verifiable without being linkable to individual choices. You can confirm that 847 people voted in a precinct without revealing which 847 people voted which way.

  2. No receipt exists that a coercer can demand. The voter leaves the process with no artifact — no photograph, no cryptographic token, no confirmation code — that proves their specific choice to a third party.

  3. The aggregate result is publicly verifiable — meaning anyone with the published data can confirm the count — without that verification creating any pathway to individual identification.

  4. Tracking becomes useless — not illegal, useless — because the information it could harvest is no longer connected to the information that matters.

This is not a utopian description of a system that does not exist. The cryptographic building blocks — anonymous credentials, zero-knowledge proofs, verifiable shuffle networks — are real and have been implemented in research and pilot contexts. What does not yet exist, at scale, in most jurisdictions, is the political will to demand verifiability as a design requirement rather than an optional audit feature.

The villain in North Macedonia is not a party. It is a system that makes voter tracking useful — because the connection between a voter's identity and their electoral behavior has not been cryptographically severed.

Sever that connection, and the spreadsheet becomes worthless.


What is still not verifiable — and what would change it

Here is what the ODIHR report on North Macedonia's 2025 elections does not tell you, and cannot: how many votes the tracking and pressure actually moved. Whether the outcome in any specific race reflected the free choices of the electorate or the managed compliance of a monitored workforce. Whether the investigations ODIHR recommended will ever produce a prosecution, much less a remedy.

Those questions are open. They will remain open under any system where the connection between voter identity and voter choice is protected only by a rule, not by architecture.

What would change it is a system that publishes its results in machine-readable, precinct-level form the moment counting is complete — so anyone can check the numbers — and that produces a mathematically verifiable aggregate that proves every cast vote was counted without revealing any individual's choice. Not a promise. Not an audit two weeks later. A proof, published in real time, that anyone can run.

Until then, "the election was conducted in accordance with the rules" and "the result reflected the free will of the voters" are two different claims. Officials can certify the first. No one — not the monitoring mission, not the government, not the winning candidate — can independently verify the second.

That gap is where coercion lives.

See how this verifiability gap appears across different countries and election types →

Read the two-minute version of why unlinkability is a security feature, not a privacy nicety →

Explore documented gaps in election integrity systems worldwide →


Sources